Showing posts with label Authentication. Show all posts
Showing posts with label Authentication. Show all posts



New Option for Secure User Authentication Will Be Available Through the Corillian Online Banking Solution From Fiserv

OVERLAND PARK, KS, May 26, 2010 (MARKETWIRE via COMTEX) -- PhoneFactor, Inc., the leading global provider of out-of-band authentication services, today announced that it has partnered with Fiserv, Inc. (FISV 47.34+0.51+1.09%) to provide phone-based user authentication through the Corillian(R) Online banking solution. The new phone-based authentication option will be integrated into Intelligent Authentication(TM) from Fiserv, a strong multi-factor user authentication tool that is available to financial institutions that use Corillian Online. Intelligent Authentication allows financial institutions to offer both passive and active user authentication options in addition to a traditional user name and password, reducing the risk of fraud and identity theft in the online channel.
Fiserv, the leading global provider of financial services technology solutions, provides online banking and bill payment services to thousands of financial institutions, including 25 of the top 50 financial institutions in the United States.
"Financial institutions are actively seeking to minimize risk for their organization and their customers," said Geoff Knapp, vice president, Online Banking and Consumer Insights, Fiserv. "Our partnership with PhoneFactor will enable financial institutions that use Corillian Online and Intelligent Authentication to provide their account holders with a phone-based authentication option, giving them another tool to protect themselves against fraud."
PhoneFactor will provide Fiserv clients with integrated multi-factor authentication services, including user authentication and transaction verification services. PhoneFactor works by placing an automated call to the online banking user during login. The user simply answers the call and presses # (or enters a PIN) on the phone keypad to complete the login. In addition to ensuring that the legitimate user is logging in, PhoneFactor can verify specific online transactions, protecting against man-in-the-middle attacks from malware like Clampi and ZeuS, all through an out-of-band channel.
PhoneFactor will be demonstrating the integrated solution at the Fiserv Connex 2010 client conference May 24-26 in Boca Raton, Fla.
"We are pleased that the many financial institutions that use Corillian Online from Fiserv will now be able to benefit from PhoneFactor's leading authentication technology without integration obstacles," said Tim Sutton, CEO of PhoneFactor. "We believe this relationship will extend Fiserv's technology leadership position by further strengthening its highly secure application for the financial services industry."
About Fiserv Fiserv, Inc. (FISV 47.34+0.51+1.09%) is the leading global provider of information management and electronic commerce systems for the financial services industry, driving innovation that transforms experiences for financial institutions and their customers. Fiserv is ranked No. 1 on the FinTech 100 survey of top technology partners to the financial services industry. For more information, visit www.fiserv.com.
About PhoneFactor PhoneFactor is a leading provider of multi-factor authentication services. The company's award-winning platform by the same name uses any phone as a second form of authentication. PhoneFactor's out-of-band architecture and real-time fraud alerts provide strong security for enterprise and consumer applications. It is easy and cost effective to set up and deploy to large numbers of geographically diverse users. PhoneFactor was recently named to the Bank Technology News FutureNow list of the top 10 technology innovators securing the banking industry today and a finalist in 2010 SC Magazine Reader Trust Awards. Learn more at www.phonefactor.com.
Contact:
Veneta Lusk
Pierpont Communications
214-217-7300 x1310
Email Contact





SOURCE: PhoneFactor
http://www2.marketwire.com/mw/emailprcntct?id=5985A53EE1448736


Reblog this post [with Zemanta]

Posted by John B. Frank Wednesday, May 26, 2010 0 comments



New Option for Secure User Authentication Will Be Available Through the Corillian Online Banking Solution From Fiserv

OVERLAND PARK, KS, May 26, 2010 (MARKETWIRE via COMTEX) -- PhoneFactor, Inc., the leading global provider of out-of-band authentication services, today announced that it has partnered with Fiserv, Inc. (FISV 47.34+0.51+1.09%) to provide phone-based user authentication through the Corillian(R) Online banking solution. The new phone-based authentication option will be integrated into Intelligent Authentication(TM) from Fiserv, a strong multi-factor user authentication tool that is available to financial institutions that use Corillian Online. Intelligent Authentication allows financial institutions to offer both passive and active user authentication options in addition to a traditional user name and password, reducing the risk of fraud and identity theft in the online channel.
Fiserv, the leading global provider of financial services technology solutions, provides online banking and bill payment services to thousands of financial institutions, including 25 of the top 50 financial institutions in the United States.
"Financial institutions are actively seeking to minimize risk for their organization and their customers," said Geoff Knapp, vice president, Online Banking and Consumer Insights, Fiserv. "Our partnership with PhoneFactor will enable financial institutions that use Corillian Online and Intelligent Authentication to provide their account holders with a phone-based authentication option, giving them another tool to protect themselves against fraud."
PhoneFactor will provide Fiserv clients with integrated multi-factor authentication services, including user authentication and transaction verification services. PhoneFactor works by placing an automated call to the online banking user during login. The user simply answers the call and presses # (or enters a PIN) on the phone keypad to complete the login. In addition to ensuring that the legitimate user is logging in, PhoneFactor can verify specific online transactions, protecting against man-in-the-middle attacks from malware like Clampi and ZeuS, all through an out-of-band channel.
PhoneFactor will be demonstrating the integrated solution at the Fiserv Connex 2010 client conference May 24-26 in Boca Raton, Fla.
"We are pleased that the many financial institutions that use Corillian Online from Fiserv will now be able to benefit from PhoneFactor's leading authentication technology without integration obstacles," said Tim Sutton, CEO of PhoneFactor. "We believe this relationship will extend Fiserv's technology leadership position by further strengthening its highly secure application for the financial services industry."
About Fiserv Fiserv, Inc. (FISV 47.34+0.51+1.09%) is the leading global provider of information management and electronic commerce systems for the financial services industry, driving innovation that transforms experiences for financial institutions and their customers. Fiserv is ranked No. 1 on the FinTech 100 survey of top technology partners to the financial services industry. For more information, visit www.fiserv.com.
About PhoneFactor PhoneFactor is a leading provider of multi-factor authentication services. The company's award-winning platform by the same name uses any phone as a second form of authentication. PhoneFactor's out-of-band architecture and real-time fraud alerts provide strong security for enterprise and consumer applications. It is easy and cost effective to set up and deploy to large numbers of geographically diverse users. PhoneFactor was recently named to the Bank Technology News FutureNow list of the top 10 technology innovators securing the banking industry today and a finalist in 2010 SC Magazine Reader Trust Awards. Learn more at www.phonefactor.com.
Contact:
Veneta Lusk
Pierpont Communications
214-217-7300 x1310
Email Contact





SOURCE: PhoneFactor
http://www2.marketwire.com/mw/emailprcntct?id=5985A53EE1448736


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Image representing Symantec as depicted in Cru...Image via CrunchBase


VeriSign will refocus business on Internet infrastructure, naming services

May 19, 2010 | 05:36 PM


By Tim Wilson

DarkReading



VeriSign, one of the best-known names in computer security, today took a step away from the security business by selling its authentication services business to Symantec for $1.28 billion.



VeriSign's authentication business, which includes the Secure Sockets Layer (SSL) encryption certification services, a managed Public Key Infrastructure (PKI) platform, and the company's ownership stake in VeriSign Japan, contributed approximately $101.9 million to VeriSign's revenues last quarter -- about 39 percent of the company's business.



Symantec's acquisition follows the $300 million purchase of encryption pioneer PGP and the $70 million purchase of GuardianEdge, which were announced simultaneously just three weeks ago.



Continue DarkReading


Reblog this post [with Zemanta]

Posted by John B. Frank Thursday, May 20, 2010 0 comments

Image representing Symantec as depicted in Cru...Image via CrunchBase


VeriSign will refocus business on Internet infrastructure, naming services

May 19, 2010 | 05:36 PM


By Tim Wilson

DarkReading



VeriSign, one of the best-known names in computer security, today took a step away from the security business by selling its authentication services business to Symantec for $1.28 billion.



VeriSign's authentication business, which includes the Secure Sockets Layer (SSL) encryption certification services, a managed Public Key Infrastructure (PKI) platform, and the company's ownership stake in VeriSign Japan, contributed approximately $101.9 million to VeriSign's revenues last quarter -- about 39 percent of the company's business.



Symantec's acquisition follows the $300 million purchase of encryption pioneer PGP and the $70 million purchase of GuardianEdge, which were announced simultaneously just three weeks ago.



Continue DarkReading


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

The lifetime "sentence" handed down for your crime?...

"Don't Type...Swipe!"



Featured Post


Statistics show that the number of unique undetected malicious programs used to steal money from Internet users has been rising exponentially.  What follows is a post I wrote for another day...



April 30,2012: Scottsdale, AZ PIN Debit Blog - Remember back in the "old days" when people used think it was safe to type their credit or debit card numbers into boxes at a website retailers checkout page? I used to laugh (or at least shake my head in disbelief during those days)



I used to remember thinking..."Isn't that the equivalent of writing your credit or debit card number down on a piece of paper and leaving it at the Point of Sale?" (so the cashier could enter it when he/she came back from where he/she was)





Or worse yet, do you remember "the daze" when people were told by their financial institution to "type" their username and password into boxes at said financial institution's online banking site?



What were they thinking? Or were they?



Could you imagine driving or walking up to an ATM to pull out $200 cash and being asked to type in a username and password as opposed to swiping your card and entering your PIN in order to authenticate oneself?  No?   Then why on earth did they ever initially think it would work for online banking authentication?



Meanwhile, statistics such as the ones above (from 2010) graphically illustrated that the jury was no longer out, and we had all been unanimously found guilty of "innocence" (isn't that a nicer word than "naivety")




Remember all those reports we read (red) where consumers believed that it was either the retailers or the banks who were responsible for securing their cardholder data?



Who "earns" your money?  You do right?  So why do you think you are not responsible for keeping it safe?  Put another way, when you "type" your account numbers into browsers amidst all the reports that it is not safe to do so, why did you think you were not responsible for security?



Again, I always laughed (or at least shook my head in disbelief) at those reports.  I remember thinking that if I drove 150 mph without my seat belt on, do I really think the airbag is responsible for my safety and security?  Even though airbags can save lives, the chances of it doing so are reduced the more reckless we are.



Alas, now we know better... (don't we?) There's a new school of thought out there...





At the end of the day, common sense prevailed and we realized that it doesn't make sense to hand over our cardholder data on a silver platter (browser) to the bad guys.



Now we know (don't we?) that a separate machine which encrypts the cardholder data at the maghead so that it never reaches the browser is not an option, but a requirement.  (if we want to keep our money in our pockets)



What's that you say? We haven't quite learned that yet? Your living in the past dude. Remember, it's 2012 now.



The writing was on the wall as far back as 2009 and with statistics like the one's represented above, we will most certainly get there.



Now I am aware of the old saying that "You can't teach an old dog new tricks", but swiping your card and entering your PIN is not a new trick.



Swipe Ubu...Swipe!

Good Dawg!















Remember when people used to Type their Card Numbers Into Boxes on Websites?  What were we Thinking?
Reblog this post [with Zemanta]

Posted by John B. Frank Friday, April 30, 2010 0 comments

The lifetime "sentence" handed down for your crime?...

"Don't Type...Swipe!"



Featured Post


Statistics show that the number of unique undetected malicious programs used to steal money from Internet users has been rising exponentially.  What follows is a post I wrote for another day...



April 30,2012: Scottsdale, AZ PIN Debit Blog - Remember back in the "old days" when people used think it was safe to type their credit or debit card numbers into boxes at a website retailers checkout page? I used to laugh (or at least shake my head in disbelief during those days)



I used to remember thinking..."Isn't that the equivalent of writing your credit or debit card number down on a piece of paper and leaving it at the Point of Sale?" (so the cashier could enter it when he/she came back from where he/she was)





Or worse yet, do you remember "the daze" when people were told by their financial institution to "type" their username and password into boxes at said financial institution's online banking site?



What were they thinking? Or were they?



Could you imagine driving or walking up to an ATM to pull out $200 cash and being asked to type in a username and password as opposed to swiping your card and entering your PIN in order to authenticate oneself?  No?   Then why on earth did they ever initially think it would work for online banking authentication?



Meanwhile, statistics such as the ones above (from 2010) graphically illustrated that the jury was no longer out, and we had all been unanimously found guilty of "innocence" (isn't that a nicer word than "naivety")




Remember all those reports we read (red) where consumers believed that it was either the retailers or the banks who were responsible for securing their cardholder data?



Who "earns" your money?  You do right?  So why do you think you are not responsible for keeping it safe?  Put another way, when you "type" your account numbers into browsers amidst all the reports that it is not safe to do so, why did you think you were not responsible for security?



Again, I always laughed (or at least shook my head in disbelief) at those reports.  I remember thinking that if I drove 150 mph without my seat belt on, do I really think the airbag is responsible for my safety and security?  Even though airbags can save lives, the chances of it doing so are reduced the more reckless we are.



Alas, now we know better... (don't we?) There's a new school of thought out there...





At the end of the day, common sense prevailed and we realized that it doesn't make sense to hand over our cardholder data on a silver platter (browser) to the bad guys.



Now we know (don't we?) that a separate machine which encrypts the cardholder data at the maghead so that it never reaches the browser is not an option, but a requirement.  (if we want to keep our money in our pockets)



What's that you say? We haven't quite learned that yet? Your living in the past dude. Remember, it's 2012 now.



The writing was on the wall as far back as 2009 and with statistics like the one's represented above, we will most certainly get there.



Now I am aware of the old saying that "You can't teach an old dog new tricks", but swiping your card and entering your PIN is not a new trick.



Swipe Ubu...Swipe!

Good Dawg!















Remember when people used to Type their Card Numbers Into Boxes on Websites?  What were we Thinking?
Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Entrust Brings Strong Authentication to Mobile Devices - Versatile Authentication Platform Secures Consumer and Enterprise Environments



Entrust IdentityGuard Mobile enables strong enterprise authentication while protecting against latest malware threats



DALLAS
April 28 /PRNewswire/ -- No matter the type, size or vertical focus of an organization, Entrust, Inc. secures identities with one of the broadest ranges of authentication options on the market today - and all from a single strong authentication platform. With the newest release of Entrust IdentityGuard, Entrust will add the innovative Entrust IdentityGuard Mobile application, which seamlessly authenticates consumer, corporate or enterprise users using many of today's most popular smartphones.


"The consistent value of this proven platform remains its versatility and cost-effectiveness," said Entrust President and CEO Bill Conner. "We continue to add new strong authentication methods to Entrust IdentityGuard, with a focus on ease of deployment and use in any environment. And the addition of Entrust IdentityGuard Mobile places yet another proven authenticator on a device end-users already use as part of their everyday life."
Entrust IdentityGuard - Easy to Use
From transparent device authentication, unique grids cards to innovative means of leveraging smartphones for strong authentication, the newest release of Entrust IdentityGuard expands on its foundation of offering the most efficient, easy-to-use authentication methods on the market today. The platform approach allows the deployment of different authenticators based on unique requirements, increasing user acceptance and reducing usability impact.
"A good authentication method will be sufficiently easy to use that it will be accepted by users as part of the tasks they perform: The easier the method, the more likely they will acknowledge it as a part of doing business - and not seek to bypass it," said Ant Allan in a December 2009 Gartner report.(1)
Smart Authentication for your Smartphone
A key addition to the Entrust IdentityGuard versatile authentication platform, Entrust IdentityGuard Mobile is an innovative new mobile identity application that allows organizations to strongly authenticate customers, partners and enterprise users via a smartphone device. Whether for consumer, government or enterprise environments, Entrust IdentityGuard Mobile represents a cost-effective, easy-to-use approach for authenticating any end-user.
Leveraging secure out-of-band techniques, and without requiring any specialized hardware, Entrust IdentityGuard Mobile provides unique capabilities to help defeat the latest malware threat affecting online-banking users - man-in-the-browser. And while it's proven to do just that, it is equally effective as a strong authentication capability for enterprise VPN access, Web portal access or corporate desktop security. Helpful options include the ability to store and save transaction history, as well as enabling deploying organizations to easily incorporate their brand into the application.
Identities in the Enterprise
Entrust IdentityGuard Mobile provides strong authentication that easily fits into the enterprise, including support for remote access, Web, and desktop strong authentication for enterprise and government initiatives. The smartphone application can manage multiple identities on a single device, making it one of the most versatile and easy-to-use soft tokens available on the market today.
Entrust Stops Man-in-the-Browser
Coupled with Entrust's proven fraud detection platform, Entrust IdentityGuard helps enable three highly deployable and effective capabilities for thwarting man-in-the-browser malware - behavioral and transactional fraud detection; SMS authentication with transaction details; and mobile out-of-band transaction verification and signature.
Without requiring any specialized hardware, Entrust IdentityGuard Mobile securely provides one-time-passcode authentication in combination with seamless out-of-band delivery of transaction details. This combination helps defend against man-in-the-browser malware - efficiently and without user inconvenience.
Popular Mobile Platforms
Entrust IdentityGuard Mobile is designed to operate with today's leading smartphone platforms, including the Apple iPhone, RIM BlackBerry, Microsoft Windows Mobile and Symbian (Java). The new mobile authenticator will be available in summer 2010 as part of the release of Entrust IdentityGuard 9.3.
Most Authenticators, Single Solution
Entrust enables organizations to layer security - according to access requirements or the risk of a given transaction - across diverse users and applications. Entrust's authentication capabilities include username and password, IP-geolocation, device, questions and answers, out-of-band one-time passcode (delivered via voice, SMS or e-mail), grid and eGrid cards, digital certificates (in software or on smart cards/USB Tokens) and a range of one-time-passcode tokens, including Entrust IdentityGuard Mobile. Entrust also provides multiple methods of supporting mutual authentication, including picture and caption replay as well as Extended Validation (EV) SSL certificates.
Want to know more about Entrust IdentityGuard 9.3? Visit entrust.com/IdentityGuard for detailed capabilities, features and support for Entrust IdentityGuard Mobile.
(1)"Good Authentication Choices for Workforce Remote Access," Ant Allan & John Girard, Gartner, Inc., December 21, 2009.
About Entrust
Entrust provides identity-based security solutions that empower enterprises, consumers, citizens and Web sites in more than 4,000 organizations spanning 60 countries. Entrust's identity-based approach offers the right balance between affordability, expertise and service. For strong authentication, fraud detection, digital certificates, SSL and PKI, call 888-690-2424, e-mailentrust@entrust.com or visit www.entrust.com.
Entrust is a registered trademark of Entrust, Inc. in the United States and certain other countries. In Canada, Entrust is a registered trademark of Entrust Limited. All Entrust product names are trademarks or registered trademarks of Entrust, Inc. or Entrust Limited. All other company and product names are trademarks or registered trademarks of their respective owners.
SOURCE Entrust, Inc.
Reblog this post [with Zemanta]

Posted by John B. Frank Wednesday, April 28, 2010 0 comments

Entrust Brings Strong Authentication to Mobile Devices - Versatile Authentication Platform Secures Consumer and Enterprise Environments



Entrust IdentityGuard Mobile enables strong enterprise authentication while protecting against latest malware threats



DALLAS
April 28 /PRNewswire/ -- No matter the type, size or vertical focus of an organization, Entrust, Inc. secures identities with one of the broadest ranges of authentication options on the market today - and all from a single strong authentication platform. With the newest release of Entrust IdentityGuard, Entrust will add the innovative Entrust IdentityGuard Mobile application, which seamlessly authenticates consumer, corporate or enterprise users using many of today's most popular smartphones.


"The consistent value of this proven platform remains its versatility and cost-effectiveness," said Entrust President and CEO Bill Conner. "We continue to add new strong authentication methods to Entrust IdentityGuard, with a focus on ease of deployment and use in any environment. And the addition of Entrust IdentityGuard Mobile places yet another proven authenticator on a device end-users already use as part of their everyday life."
Entrust IdentityGuard - Easy to Use
From transparent device authentication, unique grids cards to innovative means of leveraging smartphones for strong authentication, the newest release of Entrust IdentityGuard expands on its foundation of offering the most efficient, easy-to-use authentication methods on the market today. The platform approach allows the deployment of different authenticators based on unique requirements, increasing user acceptance and reducing usability impact.
"A good authentication method will be sufficiently easy to use that it will be accepted by users as part of the tasks they perform: The easier the method, the more likely they will acknowledge it as a part of doing business - and not seek to bypass it," said Ant Allan in a December 2009 Gartner report.(1)
Smart Authentication for your Smartphone
A key addition to the Entrust IdentityGuard versatile authentication platform, Entrust IdentityGuard Mobile is an innovative new mobile identity application that allows organizations to strongly authenticate customers, partners and enterprise users via a smartphone device. Whether for consumer, government or enterprise environments, Entrust IdentityGuard Mobile represents a cost-effective, easy-to-use approach for authenticating any end-user.
Leveraging secure out-of-band techniques, and without requiring any specialized hardware, Entrust IdentityGuard Mobile provides unique capabilities to help defeat the latest malware threat affecting online-banking users - man-in-the-browser. And while it's proven to do just that, it is equally effective as a strong authentication capability for enterprise VPN access, Web portal access or corporate desktop security. Helpful options include the ability to store and save transaction history, as well as enabling deploying organizations to easily incorporate their brand into the application.
Identities in the Enterprise
Entrust IdentityGuard Mobile provides strong authentication that easily fits into the enterprise, including support for remote access, Web, and desktop strong authentication for enterprise and government initiatives. The smartphone application can manage multiple identities on a single device, making it one of the most versatile and easy-to-use soft tokens available on the market today.
Entrust Stops Man-in-the-Browser
Coupled with Entrust's proven fraud detection platform, Entrust IdentityGuard helps enable three highly deployable and effective capabilities for thwarting man-in-the-browser malware - behavioral and transactional fraud detection; SMS authentication with transaction details; and mobile out-of-band transaction verification and signature.
Without requiring any specialized hardware, Entrust IdentityGuard Mobile securely provides one-time-passcode authentication in combination with seamless out-of-band delivery of transaction details. This combination helps defend against man-in-the-browser malware - efficiently and without user inconvenience.
Popular Mobile Platforms
Entrust IdentityGuard Mobile is designed to operate with today's leading smartphone platforms, including the Apple iPhone, RIM BlackBerry, Microsoft Windows Mobile and Symbian (Java). The new mobile authenticator will be available in summer 2010 as part of the release of Entrust IdentityGuard 9.3.
Most Authenticators, Single Solution
Entrust enables organizations to layer security - according to access requirements or the risk of a given transaction - across diverse users and applications. Entrust's authentication capabilities include username and password, IP-geolocation, device, questions and answers, out-of-band one-time passcode (delivered via voice, SMS or e-mail), grid and eGrid cards, digital certificates (in software or on smart cards/USB Tokens) and a range of one-time-passcode tokens, including Entrust IdentityGuard Mobile. Entrust also provides multiple methods of supporting mutual authentication, including picture and caption replay as well as Extended Validation (EV) SSL certificates.
Want to know more about Entrust IdentityGuard 9.3? Visit entrust.com/IdentityGuard for detailed capabilities, features and support for Entrust IdentityGuard Mobile.
(1)"Good Authentication Choices for Workforce Remote Access," Ant Allan & John Girard, Gartner, Inc., December 21, 2009.
About Entrust
Entrust provides identity-based security solutions that empower enterprises, consumers, citizens and Web sites in more than 4,000 organizations spanning 60 countries. Entrust's identity-based approach offers the right balance between affordability, expertise and service. For strong authentication, fraud detection, digital certificates, SSL and PKI, call 888-690-2424, e-mailentrust@entrust.com or visit www.entrust.com.
Entrust is a registered trademark of Entrust, Inc. in the United States and certain other countries. In Canada, Entrust is a registered trademark of Entrust Limited. All Entrust product names are trademarks or registered trademarks of Entrust, Inc. or Entrust Limited. All other company and product names are trademarks or registered trademarks of their respective owners.
SOURCE Entrust, Inc.
Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers